Need help to verify if Malware was removed!

Discussion in 'Malware Help (A Specialist Will Reply)' started by klipscomb24, May 18, 2010.

  1. klipscomb24

    klipscomb24 Private E-2

    I went through the process but was not able to follow the ROOTREPEL process. Each time i clicked the icon it would reset the entire system. In the MGTOOLS process I ran into a couple of errors but was able to follow the process. I have not done the System Toggle process. Just wanted to submit the logs and see if you could tell if Malware, Trojans, Viruses, Worms etc was removed. System stills seems a little sluggish, and I still get the Virtual Memory error message.:confused

    I had to run SASLog twice because it was so full it started to stall.
     

    Attached Files:

  2. klipscomb24

    klipscomb24 Private E-2

    Here is the MGTOOL log
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Important Notice: A new version of SUPERAntiSpyware is available.
    • Please uninstall your current version (this is necessary).
    • Then download this SUPERAntiSpyware
    • Install this new version. It may tell you that you need to reboot to complete the installation. You must reboot at this time.
    • After the reboot, run SUPERAntiSpyware and immediately click the Check for Updates button to get more updates for the database.
    • Now run a new full scan of your system. And attach this log later.

    2. Why are you using a beta version of MBAM when the latest version is not?

    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    4. Tell me what this is, what is the software for? Important I know because it could relate to antivirus or it could be somehting else.:
    Also do you know what these small files relate to?

    • C:\WINDOWS\system32\key.~
    • C:\WINDOWS\system32\log.~
    5. Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\program files\ISTsvc\istsvc.exe
    c:\windows\wfoyf.exe
    
    Folder::
    c:\program files\ISTsvc
    
    Registry::
    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentVersion\Run]
    "bOý—o”/,E%)áfINb¥_C:\\Program Files\\ISTsvc\\istsvc.exe"=-
    "bOý—o”/,E%)áfINb«_C:\\Program Files\\ISTsvc\\istsvc.exe"=-
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    6. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this, and also attach the new log from SUPERantispyware.
     
  5. klipscomb24

    klipscomb24 Private E-2

    Thank you for your assistance. Here are the results. Also that freedom file, I've tried to delete it but cant. It is not in add/remove programs.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Almost 2 months later!

    please see this for info on the freedom.exe file I was asking about.

    I am also seeing this related file in your logs.

    • c:\windows\freedom.backup.dat

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.


    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\windows\winsysupd91.dat
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    What is this?
    C:\Documents and Settings\Owner\Desktop\fc6win.exe

    Also this is a great way to get infected! Please delete it.

    Please see our policies regarding cracks:

    Warning about Porn, Keygens, Cracks, and other Illegal Software


    Open up Malware Bytes, let it update > scan > and fix all it finds. Attach the log into your next reply.

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new MGTools.exe ensuring that ist is NOT on your desktop this time but where it should be C:\MGTools.exe

    Attach the new C:\MGlogs.zip into your next reply as well as the new MBAM log and jotti results.

    Let me know how things are running now and also address any questions I may have asked you.
     
  7. klipscomb24

    klipscomb24 Private E-2

    Again, thanks for your expertise, time and most of all your patience. Yes, 2 months, i thank God its not my computer! Trying to help out a friend.
    ok here are the files that you requested. Also its running a tad bit faster except MBAM takes forever to load. http://virusscan.jotti.org/en
     

    Attached Files:

    Last edited: Jul 22, 2010
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You did not include the correct link to the results from Jotti. :) Nor did you answer this question:

     
  9. klipscomb24

    klipscomb24 Private E-2

    Ok, i followed the steps on Jotti by navigating to the c:\windows\winsysupd91.dat. and then submitted file. The status came back as: File is empty (0 bytes)! Upload progress (bar) blank.

    The file that you questioned (C:\Documents and Settings\Owner\Desktop\fc6win.exe) must no longer exsist (might have deleted it already) cant find it.

    Thanks.

    I aslo ran a scan through Avast and came across 3 trojans that were moved to the chest.
     

    Attached Files:

    Last edited: Jul 23, 2010
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Do you know what these small files relate to?

    • C:\WINDOWS\system32\key.~
    • C:\WINDOWS\system32\log.~
    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    File::
    c:\windows\winsysupd91.dat
    
    DirLook::
    C:\KA
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running now and do not forget to address my questions.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds